Courseiva

CEH Enumeration and System Hacking Practice Question

A security auditor runs SNMPwalk against a network device using the default community string 'public' and obtains extensive system information. Which THREE of the following are effective countermeasures to prevent unauthorized SNMP enumeration?

⚠ Common exam trap

The CEH exam often tests the misconception that changing the community string to another well-known default like 'private' is a valid security measure, when in fact any default string is easily guessed and should be replaced with a complex, unique string.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement an access control list (ACL) limiting SNMP access to management hosts

Option B is correct because an ACL restricting SNMP access to specific management host IP addresses prevents unauthorized hosts from querying the SNMP agent, blocking enumeration from untrusted sources. Option D is correct because changing the default 'public' community string to a complex, non-guessable value removes the trivially known credential that allowed the auditor's SNMPwalk to succeed. Option E is correct because SNMPv3 with authentication (authNoPriv/authPriv) and encryption (priv) eliminates cleartext community-string authentication and provides cryptographic verification of users, preventing unauthorized enumeration. Option A, while it would stop SNMP enumeration, is not an effective general countermeasure since it disables legitimate management/monitoring functionality rather than securing it. Option C is incorrect because 'private' is itself a well-known default community string and using it for read-only access still leaves the device vulnerable to trivial enumeration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable SNMP entirely on all devices

    Why it's wrong here

    Disabling SNMP entirely on all network devices would indeed eliminate the vulnerability to `snmpwalk` by removing the service. However, SNMP is a critical protocol for network monitoring, performance management, and configuration backup in many enterprise environments. Completely disabling it would severely impair legitimate network operations, making it an impractical and often unacceptable solution for maintaining visibility and control over infrastructure.

  • ✓

    Implement an access control list (ACL) limiting SNMP access to management hosts

    Why this is correct

    Implementing an Access Control List (ACL) on network devices or firewalls is a highly effective security measure. An ACL can be configured to permit SNMP queries only from specific, authorized IP addresses belonging to network management stations. This significantly reduces the attack surface by preventing unauthorized hosts from even attempting to enumerate device information via `snmpwalk`, thereby mitigating the risk without disabling essential monitoring capabilities.

  • ✗

    Set the community string to 'private' for read-only access

    Why it's wrong here

    Setting the community string to 'private' for read-only access is a poor security practice because 'private' is a widely known default community string, similar to 'public'. Attackers commonly attempt these default strings during reconnaissance, making devices configured with 'private' just as vulnerable to unauthorized enumeration as those using 'public'. This offers no meaningful protection against an `snmpwalk` attack.

  • ✓

    Change the community string from 'public' to a complex string

    Why this is correct

    Changing the default 'public' community string to a complex, non-guessable string significantly enhances SNMP security. A strong community string acts as a password, preventing trivial enumeration attempts by attackers who rely on common defaults. This makes it much harder for tools like `snmpwalk` to successfully query device information without prior knowledge of the specific, complex string, thereby protecting sensitive configuration data.

  • ✓

    Upgrade SNMP to version 3 with authentication and encryption

    Why this is correct

    Upgrading to SNMP version 3 (SNMPv3) provides robust security features that are absent in earlier versions. SNMPv3 incorporates strong authentication mechanisms, ensuring that only authorized users can access device information, and encryption, which protects the confidentiality of data exchanged. These features effectively prevent unauthorized `snmpwalk` operations by requiring valid credentials and securing the communication channel against eavesdropping and tampering.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.